All of lore.kernel.org
 help / color / mirror / Atom feed
* user_r/sysadm_r/staff_r/unconfined_r
@ 2014-11-04 11:37 Russell Coker
  2014-11-04 13:31 ` user_r/sysadm_r/staff_r/unconfined_r Sven Vermeulen
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Russell Coker @ 2014-11-04 11:37 UTC (permalink / raw)
  To: selinux

The role separation seems to give no benefit apart from sysadm_r/unconfined_r given that we have seuser based constraints and MCS labels to separate users and that they all use the same types.

The current policy doesn't support even logging in with a user other than unconfined_r on Debian/Unstable without significant changes.

Is there any reason for not ripping out all but 2 roles, one for root (and other sysadmin accounts but not GNOME/KDE sessions) and the other for regukar users?

Doing that will make the policy smaller and simpler (for us and users) while not losing any functionality for most users. Where most users probably means everyone who doesn't develop their own policy. The people who do develop their own policy which depends on multiple roles probably have to do plenty of work on systems with the current policy anyway.

I think that sysadm_r/unconfined_r should not transition for programs like gpg.

NB staff_r is my invention. Before that we only had sysadm_r and user_r. I invented staff_r before MCS and the seuser constraints were developed. 
-- 
Sent from my Samsung Galaxy Note 3 with K-9 Mail.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2014-11-05 16:01 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-11-04 11:37 user_r/sysadm_r/staff_r/unconfined_r Russell Coker
2014-11-04 13:31 ` user_r/sysadm_r/staff_r/unconfined_r Sven Vermeulen
2014-11-04 14:11   ` user_r/sysadm_r/staff_r/unconfined_r Russell Coker
2014-11-04 14:38 ` user_r/sysadm_r/staff_r/unconfined_r Dominick Grift
2014-11-05 10:23   ` user_r/sysadm_r/staff_r/unconfined_r Miroslav Grepl
2014-11-05 16:00 ` user_r/sysadm_r/staff_r/unconfined_r Dominick Grift

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.